From owner-freebsd-doc Wed Jan 6 11:50:11 1999 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id LAA28004 for freebsd-doc-outgoing; Wed, 6 Jan 1999 11:50:11 -0800 (PST) (envelope-from owner-freebsd-doc@FreeBSD.ORG) Received: from freefall.freebsd.org (freefall.FreeBSD.ORG [204.216.27.21]) by hub.freebsd.org (8.8.8/8.8.8) with ESMTP id LAA27989 for ; Wed, 6 Jan 1999 11:50:07 -0800 (PST) (envelope-from gnats@FreeBSD.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.8.8/8.8.5) id LAA03129; Wed, 6 Jan 1999 11:50:01 -0800 (PST) Received: from sasquatch.dannyland.org (sasquatch.dannyland.org [207.229.158.70]) by hub.freebsd.org (8.8.8/8.8.8) with SMTP id LAA26767 for ; Wed, 6 Jan 1999 11:42:34 -0800 (PST) (envelope-from dannyman@sasquatch.dannyland.org) Received: (qmail 3703 invoked by uid 1000); 6 Jan 1999 19:42:28 -0000 Message-Id: <19990106194228.3702.qmail@sasquatch.dannyland.org> Date: 6 Jan 1999 19:42:28 -0000 From: dannyman@sasquatch.dannyland.org Reply-To: dannyman@sasquatch.dannyland.org To: FreeBSD-gnats-submit@FreeBSD.ORG Cc: dannyman@sasquatch.dannyland.org X-Send-Pr-Version: 3.2 Subject: docs/9351: 2.2.8-RELEASE/ERRATA.TXT should include getpwent.c semantics Sender: owner-freebsd-doc@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org >Number: 9351 >Category: docs >Synopsis: 2.2.8-RELEASE/ERRATA.TXT should include getpwent.c semantics >Confidential: no >Severity: serious >Priority: high >Responsible: freebsd-doc >State: open >Quarter: >Keywords: >Date-Required: >Class: doc-bug >Submitter-Id: current-users >Arrival-Date: Wed Jan 6 11:50:01 PST 1999 >Closed-Date: >Last-Modified: >Originator: Dan Howard >Release: FreeBSD 2.2.8-RELEASE i386 >Organization: EnterAct, LLC >Environment: 2.2.8-RELEASE >Description: There was a buffer overflow patch made to src/lib/libc/gen/getpwent.c immediately prior release of 2.2.8. A side-effect of this patch was to modify the semantics of getpwnam() such that a string that was longer than the maximum allowed for a username would still match if the first part of the string properly matched a user name. This behaviour was corrected by eivind at 1.35.2.3 of the CVS repository. As this change to getpwnam() across releases adversely impacted the behaviour of mail aliases on our system, and was somewhat tricky to diagnose, it would seem helpful to include it in the 2.2.8-RELEASE errata. >How-To-Repeat: >Fix: >Release-Note: >Audit-Trail: >Unformatted: To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-doc" in the body of the message